{"id":"CVE-2026-54875","title":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observ…","summary":"Issue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observ…","severity":"low","cwe":["CWE-208"],"vendor":"OpenSSL","product":"OpenSSL","affected":["OpenSSL >= 4.0.0 < 4.0.3","OpenSSL >= 3.6.0 < 3.6.5","OpenSSL >= 3.5.0 < 3.5.9","OpenSSL >= 3.4.0 < 3.4.8"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T16:17:08.920","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54875","references":[{"url":"https://github.com/openssl/openssl/commit/3f01bbc28f7e08211fcdc797fd43816504f94257","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/469f3e42629f4a0b5631796e20c66c92c138a3e8","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/9794ed473764839275cb701b4850f3c24d929c28","label":"openssl-security@openssl.org"},{"url":"https://github.com/openssl/openssl/commit/dddad955d5ff3e9507619cf4e0f13e9988e2197c","label":"openssl-security@openssl.org"},{"url":"https://openssl-library.org/news/secadv/20260929.txt","label":"openssl-security@openssl.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T16:39:33.266Z","cvss":3.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-29T17:17:05.164162Z"},"cvssSource":"adp","slug":"CVE-2026-54875","body":"## Overview\n\nIssue summary: A non-constant-time optimized implementation of scalar\npoint multiplication is used for SM2 private key operations on ARM64 and\nRISC-V platforms.\n\nImpact summary: An attacker able to measure the time taken by, or to observe\nthe cache-line access pattern of SM2 signing or decryption on an affected\nplatform can learn information about the secret scalar.\n\nCWE: CWE-208: Observable Timing Discrepancy\n\nDescription: On ARM64 and RISC-V processors, the SM2 curve uses an optimized\nscalar multiplication implementation whose conditional branches and table\nlook ups are chosen according to the bits of the secret scalar. The execution\ntime and the cache-access pattern therefore depend on the long-term private\nkey (during SM2 decryption) or the per-signature nonce (during SM2 signature\ngeneration), forming a timing and cache side-channel.\n\nFIPS Impact: no\nSM2 is not a FIPS algorithm and the optimized SM2 implementation is not part\nof the FIPS module.\n\nOpenSSL 4.0, 3.6, 3.5 and 3.4 are vulnerable to this issue on AArch64 and\nRISC-V.\n\nOpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.\n\nOpenSSL 4.0 users should upgrade to OpenSSL 4.0.3.\nOpenSSL 3.6 users should upgrade to OpenSSL 3.6.5.\nOpenSSL 3.5 users should upgrade to OpenSSL 3.5.9.\nOpenSSL 3.4 users should upgrade to OpenSSL 3.4.8.\n\nThis issue was reported on 2 May 2026 by Abhinav Agarwal.\nIt was independently reported on 6 June 2026 by Feng Xue.\nThe fix was developed by Igor Ustinov.\n\n-- cut (non-publishing metadata for internal use) --\nReported by: Abhinav Agarwal, Feng Xue\nFixed by: Igor Ustinov\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":20,"depthScoreParts":{"impact":20.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[{"seq":212884,"id":"CVE-2026-54875","ts":1790703746927,"field":"cvss","old":null,"new":"3.7"},{"seq":212883,"id":"CVE-2026-54875","ts":1790703746927,"field":"severity","old":"none","new":"low"}]}